oscerd opened a new pull request, #26896:
URL: https://github.com/apache/camel/pull/26896

   ## What
   
   The denial-of-service entry under _Out of scope_ tells operators to rely on 
"the relevant component-level options". The dispositions table closes findings 
about DoS / resource bounds as `BY-DESIGN: property-disclaimed`. Neither says 
what to do when a resource limit that Camel itself offers fails to enforce its 
documented value. Such a finding could therefore be closed as by-design, or 
argued up to a CVE.
   
   This PR adds one sentence to that entry. A resource limit that Camel offers, 
such as `maxDecompressedSize` on the Zip File and Tar File data formats, is 
defence in depth for a property the framework does not claim. A defect that 
stops it enforcing its documented value is therefore a bug, fixed as 
`VALID-HARDENING` rather than published as a CVE.
   
   This matches how CAMEL-24166 was handled: `maxDecompressedSize` was skipped 
in iterator/splitter mode, and it was fixed as a bug without a CVE. The 
`BY-DESIGN` row cites _Out of scope_ as its authority, so the table and the 
prose stay consistent.
   
   ## Testing
   
   - `mvn -pl docs generate-resources` (doc symlinks and `xref-check`) passes, 
with no generated changes.
   - The new text is plain prose with monospace only: no attributes, xrefs or 
anchors.
   
   _Claude Code on behalf of oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to